Latest CVE Feed
-
9.3
HIGHCVE-2010-0987
Heap-based buffer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via crafted embedded fonts in a Shockwave file.... Read more
- Published: May. 13, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0986
Adobe Shockwave Player before 11.5.7.609 does not properly process asset entries, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted Shockwave file.... Read more
- Published: May. 13, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0995
Stack-based buffer overflow in Internet Download Manager (IDM) before 5.19 allows remote attackers to execute arbitrary code via a crafted FTP URI that causes unspecified "test sequences" to be sent from client to server.... Read more
Affected Products : internet_download_manager- Published: May. 06, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2020-1051
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1174, CVE-2020-1175, CVE-2020-1176.... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_server windows +1 more products- Published: May. 21, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-1236
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1208.... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_server windows +1 more products- Published: Jun. 09, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2007-1751
Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to access an uninitialized or deleted object, related to prototype variables and table cells, aka "Uninitialized Memory Corruption Vu... Read more
- Published: Jun. 12, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2020-3194
A vulnerability in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exists due to insufficient validation of ... Read more
Affected Products : webex_meetings_server webex_meetings_online webex_meetings webex_network_recording_player- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-10016
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. An application may be able to execute arbitrary code with kernel privileges.... Read more
- Published: Dec. 08, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2010-0833
The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storage Systems and possibly other products, uses "SetPassword logic" when running as part of a root service, wh... Read more
- Published: Jul. 28, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0824
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed WOPT (0x80B) record, aka "Excel Record Memory Corruption Vulnerability," a different ... Read more
- Published: Jun. 08, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0815
VBE6.DLL in Microsoft Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Visual Basic for Applications (VBA), and VBA SDK 6.3 through 6.5 does not properly search for ActiveX controls that are embedded in documents, which allows rem... Read more
- Published: May. 12, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0037
Buffer overflow in Image RAW in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted DNG image.... Read more
- Published: Jan. 20, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0766
Integer overflow in the Swap4 function in valet4.dll in Luxology Modo 401 allows user-assisted remote attackers to execute arbitrary code via a .LXO file containing a CHNL subchunk associated with an invalid length.... Read more
Affected Products : modo- Published: Mar. 03, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0818
The MPEG-4 codec in the Windows Media codecs in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly handle crafted media content with MPEG-4 video encoding, which allows remote attackers to ... Read more
- Published: Sep. 15, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0177
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, frees the contents of the window.navigator.plugins array while a reference to an array element is still active, which allows remote attackers to execute... Read more
- Published: Apr. 05, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0679
Multiple stack-based buffer overflows in the HyleosChemView.HLChemView ActiveX control (HyleosChemView.ocx) in Hyleos ChemView 1.9.5.1 allow remote attackers to execute arbitrary code via a large number of white space characters in the filename argument t... Read more
Affected Products : chemview- Published: Feb. 22, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0658
Multiple integer overflows in Skia, as used in Google Chrome before 4.0.249.78, allow remote attackers to execute arbitrary code in the Chrome sandbox or cause a denial of service (memory corruption and application crash) via vectors involving CANVAS elem... Read more
- Published: Feb. 18, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0657
Google Chrome before 4.0.249.78 on Windows does not perform the expected encoding, escaping, and quoting for the URL in the --app argument in a desktop shortcut, which allows user-assisted remote attackers to execute arbitrary programs or obtain sensitive... Read more
- Published: Feb. 18, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0555
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving the product'... Read more
Affected Products : windows_server_2008 internet_explorer windows_2000 windows_server_2003 windows_vista windows_xp- Published: Feb. 04, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0599
Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 does not encrypt XML RPC sessions from operat... Read more
- Published: May. 27, 2010
- Modified: Apr. 11, 2025